Legal
Privacy Policy
Last updated: 12 July 2026
JobStack ("JobStack", "we", "us" or "our") provides a job, client, quoting and email management platform for trade businesses, available at jobstack.com.au and through our iOS and Android apps (together, the "Service"). This policy explains what personal information we collect, how we use it, who we share it with, and the choices you have.
We are an Australian business and handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. The information we collect
Account information
- Your name, email address and password when you register directly.
- Your name, email address and profile picture from Google if you sign in with Google.
- Your role and membership in each workspace you belong to.
Workspace content
The Service stores the business records your workspace creates and uploads: jobs, clients and their contact details, quotes, tasks, schedules, timesheets, expenses, variations, notes, comments, photos and file attachments. This content frequently contains personal information about third parties — for example, the names, email addresses and phone numbers of your clients, builders and suppliers. Your workspace controls this content; we process it to provide the Service.
Email data
Emails enter the Service in two ways, both initiated by you:
- Forwarded email — each workspace has a unique ingestion address (e.g. yourbusiness@in.jobstack.com.au). Emails you forward or auto-forward there are received via our email provider (Postmark) and stored in your workspace.
- Connected Gmail mailboxes — a workspace admin can connect a Gmail account. See "Google user data" below for exactly what this involves.
Stored emails include the sender, recipients, subject, body and attachments. They are visible only to members of your workspace with an appropriate role.
Billing information
Subscriptions are processed by Stripe. We store your subscription status, plan and billing history reference, and Stripe stores your payment card details — full card numbers never touch our servers. Stripe's handling of your data is described in the Stripe Privacy Policy.
Device and usage information
- Log data such as IP address, browser type and pages accessed, used for security and debugging.
- If you use the mobile app and enable notifications, a push notification token for your device.
- Details you submit through our contact form (name, email, company, phone, message).
2. Google user data
JobStack uses Google OAuth for two separate, optional purposes. In both cases you grant access on Google's consent screen and can revoke it at any time.
Signing in with Google
We request your basic profile (name, email address and profile picture) solely to create and sign in to your JobStack account.
Gmail mailbox sync
If a workspace admin connects a Gmail account, we request read-only
access to that mailbox (the gmail.readonly scope).
We use this access only to:
- Periodically fetch new incoming messages and their attachments so they appear in your workspace inbox.
- Link those messages to the relevant jobs and clients, with the help of the AI features described below.
We never send, delete, modify or label messages in a connected mailbox, and we cannot — the access we request is read-only.
JobStack's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We only use Gmail data to provide the user-facing email features described above.
- We do not sell Gmail data, use it for advertising, or use it to train generalised artificial intelligence or machine learning models.
- No human reads your Gmail data except (a) with your explicit permission, e.g. when you ask us to investigate a support issue; (b) where necessary for security purposes such as investigating abuse; or (c) where required by law.
You can disconnect a mailbox at any time in Settings → Mailboxes, which deletes our stored access tokens, or revoke JobStack's access from your Google Account permissions page.
3. AI features
JobStack includes AI features that classify incoming emails, suggest links between emails and jobs, draft job summaries and draft quotes. To provide these features we send the relevant content (for example, the text of an email or the sources you select for a quote) to OpenAI, our AI processing provider, via its API.
- Content sent to OpenAI's API is not used by OpenAI to train its models.
- AI output is presented as suggestions or drafts for a person in your workspace to review; every AI action is logged on the job timeline.
- Workspace admins can adjust or restrict automatic AI behaviour in Settings → AI.
4. How we use your information
- To provide, maintain and improve the Service.
- To operate the email ingestion, AI triage, quoting and scheduling features you use.
- To process subscription payments and send billing communications.
- To send service communications such as workspace invitations, daily digests and push notifications you have enabled (you can opt out of digests and notifications in the app).
- To respond to enquiries and provide support.
- To secure the Service, prevent abuse and comply with our legal obligations.
We do not sell personal information, and we do not use your workspace content or email data for advertising.
5. Who we share information with
We share information only with service providers who help us operate the Service, and only to the extent needed:
- Hosting and infrastructure providers — application hosting, databases, file storage and backups.
- Stripe — subscription billing.
- Postmark — inbound email ingestion and outgoing transactional email.
- OpenAI — AI processing as described in section 3.
- Google — sign-in and Gmail sync, where you have connected them.
- Expo — delivery of mobile push notifications.
We may also disclose information where required by law, to enforce our terms, or to protect the rights, property or safety of JobStack, our users or the public. If JobStack is involved in a merger, acquisition or asset sale, information may be transferred as part of that transaction; we will notify you before your information becomes subject to a different privacy policy.
Some of our providers store or process data outside Australia (including in the United States). Where they do, we take reasonable steps to ensure they handle personal information consistently with this policy and the APPs.
6. Security
- All traffic to and from the Service is encrypted in transit (HTTPS/TLS).
- Mailbox OAuth tokens are stored encrypted, and passwords are hashed using bcrypt.
- File attachments are stored on private storage and served only to authenticated members of the owning workspace.
- Access to workspace data is enforced per-request based on your workspace membership and role.
No method of transmission or storage is completely secure, but we work to protect your information using industry-standard practices, and we will notify affected users and the OAIC of any eligible data breach as required by the Notifiable Data Breaches scheme.
7. Data retention and deletion
- Workspace content is retained while the workspace is active so your business records remain available to you.
- Disconnecting a Gmail mailbox immediately deletes our stored tokens and stops all syncing. Previously synced emails remain in your workspace unless you delete them.
- You can delete your account from your profile page. If you are the sole owner of a workspace, contact us to arrange deletion of the workspace and its content.
- Deleted data is removed from our production systems promptly and from backups within our standard backup rotation period (up to 35 days).
- We may retain limited records (e.g. invoices) where required for tax, accounting or legal purposes.
8. Your rights
You may request access to, or correction of, the personal information we hold about you by contacting us using the details below. We will respond within a reasonable period. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
If your personal information is contained in another business's workspace (for example, you are a client of a trade business that uses JobStack), that business controls the record; we suggest contacting them directly, and we will assist them with any access, correction or deletion request.
9. Cookies
We use cookies that are necessary to run the Service — session authentication and CSRF protection. We do not use third-party advertising or cross-site tracking cookies.
10. The mobile app
- The app requests camera and photo library access only when you attach photos to jobs, tasks or comments.
- Notification permission is requested only if you enable push notifications.
- The app caches recent workspace data on your device (for up to 24 hours) so crews can work with poor reception; this cache is cleared when you log out.
11. Children
The Service is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16.
12. Changes to this policy
We may update this policy from time to time. If we make material changes we will notify you by email or through the Service before the changes take effect. The "Last updated" date at the top of this page shows when it was last revised.
13. Contact us
For privacy questions, or to make an access, correction or deletion request, email privacy@jobstack.com.au or use our contact form.